1 Data Controller
Email: plan.trip.support@gmail.com
2 Data processed and purposes
2.1 Data saved locally (only on your device)
Plan Trip saves in your browser's localStorage the following data, which remains exclusively on your device and is never sent to our servers:
| Data | Purpose | Legal basis |
|---|---|---|
| Trip names and dates | Itinerary management | Art. 6.1.b GDPR |
| Itinerary content (cities, accommodations, activities, prices, links) | Trip planning | Art. 6.1.b GDPR |
| Theme preference (light/dark) | Interface personalisation | Art. 6.1.f GDPR |
| Language preference (Italian/English) | Interface personalisation | Art. 6.1.f GDPR |
You can delete this data via: Browser developer tools → Application → Local Storage.
2.2 Data processed with Google Drive sync (optional)
The synchronisation feature is completely optional and requires your explicit consent via Google account sign-in.
| Data | Source | Where stored | Purpose |
|---|---|---|---|
| Google email address | Google OAuth2 | localStorage (your device only) | Account display |
| Google display name | Google OAuth2 | localStorage (your device only) | Account display |
| OAuth2 access token | Google Identity Services | localStorage (expires ~1 hour) | Drive API authentication |
| Itinerary content | User input | Google Drive (private app folder) | Backup and cross-device sync |
Sync data is in appDataFolder, accessible only by Plan Trip. To revoke access: myaccount.google.com/permissions.
2.3 Data processed with trip sharing (optional)
If you choose to share a trip via link, the app saves a copy of the trip in your regular Google Drive ("Plan-Trip" folder, visible in your Drive) and sets public read permissions to allow access to anyone with the link.
| Data | Where stored | Who can access | Purpose |
|---|---|---|---|
| Full itinerary copy (JSON) | Google Drive ("Plan-Trip" folder) | Anyone with the link (read only) | Trip sharing |
Shared files can be deleted from your Google Drive at any time.
2.4 Data processed with real-time collaboration (optional)
If you enable collaboration, trip data is synchronised in real time via Firebase Firestore (Google Cloud). Authentication is handled by Firebase Authentication using your Google account.
| Data | Source | Where stored | Purpose |
|---|---|---|---|
| Google UID, email and name | Firebase Authentication | Firebase Auth + Firestore | Collaborator identification |
| Full itinerary data | User input | Firebase Firestore | Real-time synchronisation |
| Lock state (who is editing) | Generated by the app | Firebase Firestore | Edit conflict prevention |
| Collaborator emails | Entered by the owner | Firebase Firestore | Access control |
Firestore data can be removed by stopping collaboration from the sharing panel.
3 Third-party services
3.1 CARTO (maps)
Interactive maps use CARTO (basemaps.cartocdn.com). When you view a map, your browser transmits your IP and the viewed region to CARTO.
Privacy: carto.com/privacy
3.2 Google Maps (external links)
Some cards display links to Google Maps. Clicking is voluntary and triggers data transmission to Google under their own terms.
3.3 Google (auth and Drive)
If you enable sync, Google scripts are loaded from accounts.google.com and apis.google.com. Google processes data under their own privacy policy: policies.google.com/privacy.
3.4 Firebase (real-time collaboration)
If you enable collaboration, Firebase scripts are loaded from firebaseio.com and googleapis.com. Firebase is a Google Cloud service and data is processed under Google's privacy policy: firebase.google.com/support/privacy.
4 International transfers
Google LLC (USA), including Firebase, is covered by the EU–US Data Privacy Framework (EU adequacy decision, 10 July 2023). CARTO uses datacentres in the European Union.
5 Retention period
| Data | Retention |
|---|---|
| Itinerary data (localStorage) | Until voluntary deletion or browser clearing |
| Google email and name | Until explicit logout from the app |
| Google access token | ~1 hour (technical expiry), renewed if logged in |
| Data on Google Drive | Until deletion from the cloud panel or access revocation |
| Data on Firebase Firestore | Until collaboration is stopped or the trip is deleted |
6 Your rights (GDPR Art. 15–22)
Contact: plan.trip.support@gmail.com
You may lodge a complaint with your national data protection authority.
7 Security
8 Policy changes
Any changes will be communicated by updating the date at the top of this page. Continued use of the app after changes constitutes acceptance of the updated policy.
9 Cookie Policy
For information on cookies see our Cookie Policy.